Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 b724ed74c408aae4…

MALICIOUS

Office (OLE) / .EXE

9.5 KB Created: 1999-03-30 15:47:00 Authoring application: Microsoft Word for Windows 95
MD5: 3789bbb681cb8ddbf615971607b9b5fa SHA-1: 755d0fa71638043d4af95ebb041ec866679440b6 SHA-256: b724ed74c408aae408da412a4ad82a36bd66cf88d11e4b4f8ae60c0f8848a674
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is detected by ClamAV as Legacy.Trojan.Agent-454, indicating a known malicious signature. The document body contains unusual strings and references to AutoOpen and Aphrodite, suggesting an attempt to trigger an embedded macro or exploit. The file's metadata indicates it's an OLE file created with an old version of Microsoft Word, further supporting the 'legacy' detection.

Heuristics 1

  • ClamAV: Legacy.Trojan.Agent-454 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Legacy.Trojan.Agent-454